Britain's AI Bet, Part Two: Open, Closed, and the Question of Who Controls the Machines

The second in an Arcara Strat series on artificial intelligence and the next industrial revolution. Part one examined how AI's threat to jobs and its promise of reindustrialisation are landing in the United Kingdom. Part two turns to the question now dividing the industry's most powerful figures: should frontier AI be open or closed, and what does the answer mean for Britain, the West and the contest with China? 

If part one was about what AI does, part two is about who controls it, and the question has just become the most consequential fault line in the technology's politics. On 24 July 2026, a coalition of 25 companies, including Nvidia, Microsoft, Meta, IBM, Palantir, Hugging Face and the Linux Foundation, published an open letter, "Open Weights and American AI Leadership." Nvidia's chief executive Jensen Huang chose the moment for his first ever post on X, writing that "open models strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty." Within days, the chief executives of Microsoft and Google had added public endorsements. According to reporting, OpenAI and Anthropic have at the same time lobbied Washington to restrict open models, even as some of their leaders voice public support for the principle. The industry, in other words, is at war with itself over its own foundations.

A necessary clarification: open, open-weight and closed

The debate is often muddled by loose terminology, so it is worth being precise. A closed model, such as the flagship systems from OpenAI or Anthropic, is accessed only through a controlled interface; the underlying weights, the numerical parameters that constitute the trained model, stay with the developer. An open-weight model, such as Meta's Llama family or the Chinese models now causing a stir in Washington, makes those weights freely downloadable, so that anyone can run, fine-tune and build on the model on their own hardware. Fully open source, in the strict sense familiar from software, would also mean releasing the training data, the data-cleaning methods and the complete training code, which most "open" AI releases do not. What Huang and his co-signatories are defending is principally an open-weight ecosystem, not total transparency. The distinction matters, because the risks and benefits differ depending on exactly what is being released.

The case for open

The strongest arguments for open models are not narrowly commercial. They are about power, security and sovereignty.

The first is competition and diffusion. Open weights lower the barrier to entry, allowing start-ups, universities, hospitals, banks and manufacturers to build on capable models without paying escalating fees to a handful of incumbents or being locked into a single vendor's ecosystem. This is the same dynamic that made open-source software, from Linux to Android, the foundation on which most of the modern internet and much of the US military's own infrastructure is built. The historical analogy is the coalition's central rhetorical weapon: restricting open models now, they argue, would repeat a mistake that was narrowly avoided with software in the 1980s.

The second, and the one doing the most work in the current debate, is sovereignty. For any country that cannot realistically build frontier models from scratch, and that includes almost every country other than the United States and China, open weights are the difference between having indigenous AI capability and renting it from abroad. Governments and businesses worried about national security and economic competitiveness have limited appetite for depending on a single foreign focal point for so critical a technology. Open models let a country adapt systems to its own language, culture, laws and needs, keep sensitive data within its own borders, and build domestic expertise rather than surrendering it to offshore platforms. For a mid-sized power, this is not an abstract preference. It is the practical basis of technological self-determination.

This is not merely a theoretical claim, and there is now hard evidence for how widely it is held. A 2025 Linux Foundation survey of organisations across the United States, Europe and Asia-Pacific, The State of Sovereign AI, found that 45% regard open source as essential to achieving it, with control over data (72 per cent) and national security (69 per cent) the leading motives. Respondents ranked transparency and auditability, security and trust, and freedom from vendor lock-in as the qualities that make open foundations valuable, precisely the attributes a country needs to be sure no single foreign provider can capture the technology. Strikingly, 94 per cent also viewed global collaboration on open source as essential to building sovereign systems, which cuts against the intuition that sovereignty means going it alone. On this evidence, openness and shared standards are seen not as a threat to national control but as the route to it: a shared, inspectable foundation that deepens collective understanding of these systems while leaving each country in command of its own stack and data.

The third is transparency and accountability, and it carries a democratic charge. A closed model can only be trusted; an open one can be inspected. That inspectability allows independent researchers to probe models for flaws, security vulnerabilities and, importantly, embedded biases, including biases their own creators never intended or noticed. A closed system that quietly disadvantages particular communities in lending, hiring or policing decisions is far harder to detect and challenge from the outside. Open models allow the wider world to hold the technology to account, which is one safeguard against AI hardening into a tool that entrenches marginalisation. This is a serious argument, and it is among the most compelling in the open camp's case.

There is also a geopolitical version of the argument, advanced most forcefully by Huang. Chinese laboratories, notably DeepSeek and Moonshot AI, whose Kimi K3 model was released in July and ranks among the most capable anywhere, are producing increasingly strong open models. Huang's contention is that American openness, rather than retreat, is the better response: that widely diffused open models built on Western foundations keep the world building within a Western technological ecosystem, and that the proliferation of cheap AI ultimately drives demand for the chips his company sells. He goes so far as to argue the probability of China pushing American firms out of the market is "zero," and dismisses fears of hidden "backdoors" in Chinese models on the ground that a downloaded model can be fine-tuned and controlled by the user.

The case for caution

The counter-arguments are equally serious, and they explain why parts of the industry and the US national-security establishment are uneasy.

The first is proliferation. An open-weight model cannot be recalled. Once released, it can be downloaded, copied and fine-tuned by anyone, including to strip out the safety measures its developers built in. The concern is not hypothetical: open models have already been adapted for purposes their creators did not sanction, and reporting in recent years documented Chinese researchers using Meta's Llama to build a military tool. Part one of this series described how two of the most careful laboratories in the field, in a single month, had models under evaluation break out of their test environments and compromise the real systems of outside organisations, in each case pursuing a narrow goal to lengths their designers never intended once containment slipped.The worry is that open release hands that same capability, minus the guardrails, to anyone who wants it, in domains from cyber-offence to biological weapons.

Openness has a strategic answer to at least the geopolitical half of this concern, put most forcefully by Nvidia's Jensen Huang. Even if a rival such as China takes open Western weights and fine-tunes them into models of its own, he argues, those systems are still built on and within the American, or Western, technology stack, much as the world's computing has been built on open foundations since the 1990s. Keeping the world building on Western rails is on this view itself a strategic asset, and it preserves an option of last resort: should a competitor ever turn that capability against the West, the United States still controls the genuine frontier and could move to restrict or close off its most advanced models at that point. Openness now, in other words, need not mean openness forever. It is a strong answer to the worry about state competitors, and a weaker one to the worry about non-state actors, for whom belonging to anyone's technology stack is no constraint at all.

The second is intellectual property and the distillation problem. US officials, including the White House science and technology adviser, Michael Kratsios, have accused Chinese developers of using "distillation," training their own models to imitate the outputs of leading American systems, to close the gap cheaply. From this vantage, frontier models are valuable strategic assets, and open or semi-open release accelerates a competitor's ascent at America's expense. This is the logic behind the restrictions that OpenAI and Anthropic have reportedly urged on Washington, and behind the broader securitisation of AI now under way.

The third is a caveat to the strategic argument just made. The reassurance that openness can be wound back as a last resort is real but only partial, because an open-weight model, once released, cannot be recalled. A rival that has taken Western weights and built an independent capability on them is not tied to the source by standards, updates or dependencies the way an operating system would bind it; closing the frontier later would slow that rival's next advance, not undo the capability already in its hands. The "tech stack" framing therefore describes a genuine near-term advantage while overstating how much lasting leverage it confers. It is coherent to believe strongly in open models for reasons of sovereignty, competition and transparency, and to accept the near-term strategic logic, while remaining sober about how firmly openness binds an adversary to the West over time.

Where Britain sits

For the United Kingdom, the balance of these arguments tilts, though not without tension. Britain is not going to out-spend the United States or China at the frontier, as part one argued in the context of chips. That makes the sovereignty case for open models unusually resonant here: open weights are the most plausible route to genuine indigenous AI capability, to keeping public-sector and sensitive data under British control, and to building on shared foundations rather than depending wholly on a few American providers. A country pursuing reindustrialisation and technological self-determination has structural reasons to favour an open ecosystem.

Set against that, Britain has real security equities and deep intelligence and defence ties to the United States, which is moving towards a more restrictive posture. A UK that embraced openness while Washington moved to close would face awkward questions about alignment with its most important ally, particularly in defence-adjacent AI. The likely landing point, and the one worth watching for, is a differentiated approach: openness encouraged for the broad diffusion of AI through the economy, where the productivity and sovereignty gains are greatest, alongside tighter controls at the genuine capability frontier and in security-sensitive domains. The current signals from Washington point the same way, with officials reportedly leaning towards regulating specific high-risk models individually rather than imposing a blanket ban.

What businesses and financial institutions should watch

The regulatory trajectory is the first thing to monitor. Whether the United States opts for targeted, model-by-model restrictions or something broader will shape the entire global market, and a fragmentation of the AI landscape into rival Western and Chinese ecosystems, each with its own compliance regime, is a live possibility with direct consequences for any firm operating across both.

For businesses, the strategic implication is to avoid over-dependence on any single model or provider, whether open or closed. A sensible posture combines the control, data-security and cost advantages of open-weight models for many internal applications with access to frontier closed models where raw capability justifies it. Firms in regulated sectors should weigh where their data physically resides and who can inspect it, considerations on which open models often have the advantage. And every organisation should recognise that the open-versus-closed question is no longer merely technical. It is becoming a matter of national policy, trade and security, and the rules are being written now.

The deeper point is that this debate is not really about software licences. It is about who holds the most powerful productive tool of the coming era, and on what terms the rest of the world may use it. Britain's answer will help determine whether it emerges from this industrial revolution as a builder with genuine capability of its own, or as a renter dependent on decisions made elsewhere.

Next
Next

Britain's AI Bet, Part One: Industrialisation, Jobs and the Transition Gap